Key Takeaways
- Most states have moved from ad‑hoc AI experiments to centralized governance frameworks, but day‑to‑day responsibility usually rests with the individual agency that deploys the system.
- The “handoff” from central oversight to agency ownership varies widely—some states use a multidisciplinary review board, while others rely on a simple intake process.
- After an AI tool goes live, agencies are expected to monitor performance, audit for bias or error, and follow incident‑response procedures; central offices typically intervene only for security or privacy breaches.
- Experts warn of a “diffusion of responsibility” when no single person is named accountable for each deployed AI system, which can hinder timely problem‑solving.
- Embedded AI capabilities in off‑the‑shelf software create a stealthy risk; states are treating procurement as a checkpoint to vet hidden AI features.
- Human behavior drives “shadow AI” when approved tools are slow or unclear, suggesting that policies alone cannot curb unauthorized use.
- NASCIO data show rapid maturation of AI governance: 98 % of states now have enterprise generative‑AI policies, and over 44 states have an AI officer or equivalent.
- The next governance phase will focus on answering operational questions—who owns each system, who monitors performance, and when to retire or expand a tool.
Who Sets the Initial Rules?
States have increasingly centralized AI governance, but centralization does not mean that a single office controls every decision. In many states, CIO offices or emerging‑technology teams have become responsible for creating frameworks by developing policies, reviewing use cases, maintaining inventories and ensuring agencies understand the risks before deploying AI. “It’s not the same across the board,” said Meredith Ward, deputy executive director of the National Association of State Chief Information Officers (NASCIO). “If you’ve seen one state, then you’ve seen one state, meaning 50 states could have 50 different ways of doing things.” Maryland’s Department of Information Technology, for example, establishes guardrails for AI use—including security, privacy and data standards—and requires agencies to complete an AI intake process before deployment. Once approved, ownership moves back to the individual agency. California mirrors this approach, with the Department of Technology setting statewide policy while agencies retain responsibility for operation, monitoring, risk management and compliance. Pennsylvania adds a multidisciplinary review led by the Emerging Technology Office, the Generative AI Governing Board, privacy and security officers, and legal counsel before any generative‑AI system moves from idea to implementation.
Ownership After Launch
Building an approval process is relatively straightforward compared with pinpointing what happens after an AI system goes live. If an AI tool produces inaccurate recommendations, introduces bias or creates unexpected outcomes, states generally do not expect a central AI office to step in and manage each issue. Instead, agencies using the technology are expected to monitor performance, understand limitations and address problems. In Maryland, Boyce said it does fall on individual agencies to manage AI issues in the first instance. “That includes monitoring performance, auditing outputs for accuracy and bias, maintaining error logs, and following incident response procedures,” he noted. Security or privacy incidents, however, are routed through the state’s Security Operations Center. California operates similarly: the central technology office provides governance and oversight, but agencies remain responsible for managing deployed systems and making sure they continue meeting operational and compliance requirements.
Operational Accountability Fragmentation
Some experts say the road gets bumpier when responsibility is shared without a clear destination or a clear driver. Andrew Merluzzi, AI Innovation and Incubation Fellow at the Beeck Center, observed that while many states have made strides creating governance structures, operational accountability has not always evolved at the same pace. “Basically, states have made great progress on central governance, while AI at the operational level remains more fragmented,” Merluzzi explained. He added that big moves such as executive orders, task‑force launches or statewide AI inventories do not automatically answer questions about who handles errors when they occur. “That’s much more of an operational question, and for many states, the answer is still shaking out.” This gap can leave agencies unsure who to call when an AI model drifts or produces harmful output.
The Need for a Named Owner
Merluzzi warned that without a specific person named and responsible for each use case, governments risk what he called a diffusion of responsibility, where multiple offices may be involved but no single person is accountable for performance, monitoring or improvement. “Every deployed AI system should have a specific person named and responsible for the use cases,” he insisted. Assigning clear ownership helps ensure that when an issue arises, there is a direct line of accountability rather than a vague chain of committees.
Best Models Combine Central Standards with Local Decision‑Making
The most effective state models pair a set of central standards with considerable operational decision‑making lower down in the agencies or even on individual teams. Chief AI officers, Merluzzi said, are not necessarily meant to become the sole authority over AI. Instead, their role is to translate broad principles into repeatable practices—creating risk tiers, developing evaluation standards, establishing escalation procedures and more—while CIOs continue to focus on enterprise technology decisions such as tools, contracts and technical controls. This layered approach allows states to maintain consistency without stifling agency agility.
AI Will Show Up Anyway
Potentially one of the biggest challenges states face is that AI does not always arrive wearing an AI label. Increasingly, AI capabilities are being built into software that governments already use, even if they don’t realize it. “A productivity platform update, a customer service application or an enterprise system upgrade can introduce new AI functionality without an agency intentionally purchasing a separate AI product,” the article notes. From NASCIO’s perspective, Ward identified embedded AI capabilities as one of the biggest governance challenges facing states because software updates can introduce new AI features, expanding the potential attack surface while reducing visibility into where AI is entering government environments. The 2026 NASCIO‑Deloitte Cybersecurity Study found that 94 % of state CISOs reported actively participating in developing generative‑AI security policies, while 84 % are involved in strategy development and use‑case reviews. One state CISO framed the concern bluntly:
“GenAI is advancing faster than existing governance structures can adapt, creating growing uncertainty around security, privacy and ethical use. Vendors are increasingly embedding AI capabilities into products and services without sufficient transparency or state‑level control, effectively inflicting AI on operational environments before comprehensive risk assessments or policy frameworks can be applied.”
In response, states are turning procurement into a gate‑keeping step. Pennsylvania requires enterprise security and emerging‑technology reviews whenever AI is purchased, either as a standalone application or as part of another technology product. California’s governance framework expects agencies to evaluate embedded AI features during procurement and implementation. Maryland routes AI capabilities through its intake process before agencies deploy them, including AI features built into existing enterprise software.
Human Variable and Shadow AI
Even the most carefully designed governance framework can run into a human variable. Employees still need tools that work for the way they actually do their jobs. Ward noted that AI accountability ultimately resides with the agencies and employees utilizing these solutions. “That is where states are confronting a familiar technology problem. When approved tools are difficult to access, employees often find alternatives on their own.” Acceptable use policies have become one tool states use to manage what many call shadow AI, but policies alone cannot solve the human side of adoption. Merluzzi echoed this view, observing that restrictions alone are unlikely to solve the problem. “Employees often turn to unauthorized AI tools when the tool they need has not yet been approved, because approval processes take too long or because employees do not know which tools they are permitted to use.” Essentially, simply banning AI doesn’t eliminate use, but it does often drive it underground.
Measuring Success and the Road Ahead
For all of these remaining challenges and questions, NASCIO’s forthcoming 2026 State CIO Survey notes that state AI governance has matured relatively quickly. According to data that Ward shared from the report, 98 % of states have implemented enterprise policies governing generative AI development and use—up from 76 % in 2025. And 84 % of states have established AI advisory committees or task forces, up from 82 % in 2025, while more than 44 states now have an AI officer, director or equivalent role, primarily housed in CIO offices. States have quickly moved beyond early conversations about whether AI needs governance, with Ward noting that AI governance is now essentially operational in all states.
Merluzzi, for his part, said that the next phase of AI governance may require states to answer tougher questions: Who owns each system? Who monitors performance? What happens when results decline? When should an AI tool expand, change or be retired? Those answers will determine whether AI governance becomes more than a collection of policies and approval forms. “Because in the end, the hardest part of governing AI may not be deciding what technology governments can and should start using, but who is responsible for it after they put AI to use,” he concluded.
This summary synthesizes the original Government Technology article, preserving its core arguments, expert commentary, and illustrative quotations while presenting the information in a structured, journalist‑style format.
https://www.govtech.com/spotlight/50-states-50-different-ways-who-owns-ai-once-its-deployed

